You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用YAML文件部署Kubernetes时遭遇STS角色权限错误

解决EKS中kubectl操作的sts:AssumeRole权限拒绝问题

问题现象

执行kubectl部署Kubernetes资源时,反复出现权限错误,所有集群操作(创建角色、集群角色绑定等)均失败:

部署Deployment时的错误

kubectl apply -f k8s/deployment.yml --validate=false

An error occurred (AccessDenied) when calling the AssumeRole operation: User: <user arn> is not authorized to perform: sts:AssumeRole on resource: <cluster role arn>
E1111 21:37:30.036257   14704 memcache.go:265] couldn't get current server API group list: Get "https://5E52EE866A68FF445D9EFF54FF06C3FF.gr7.ap-south-1.eks.amazonaws.com/api?timeout=32s": getting credentials: exec: executable aws failed with exit code 254
error: unable to recognize "k8s/deployment.yml": Get "https://5E52EE866A68FF445D9EFF54FF06C3FF.gr7.ap-south-1.eks.amazonaws.com/api?timeout=32s": getting credentials: exec: executable aws failed with exit code 254

部署ClusterRoleBinding时的错误

kubectl apply -f k8s/clusterrolebinding.yml --validate=false

An error occurred (AccessDenied) when calling the AssumeRole operation: User: <<user arn>> is not authorized to perform: sts:AssumeRole on resource: <<cluster role arn>>
E1112 12:33:01.210734   35556 memcache.go:265] couldn't get current server API group list: Get "https://5E52EE866A68FF445D9EFF54FF06C3FF.gr7.ap-south-1.eks.amazonaws.com/api?timeout=32s": getting credentials: exec: executable aws failed with exit code 254
error: unable to recognize "k8s/clusterrolebinding.yml": Get "https://5E52EE866A68FF445D9EFF54FF06C3FF.gr7.ap-south-1.eks.amazonaws.com/api?timeout=32s": getting credentials: exec: executable aws failed with exit code 254 

解决方案

1. 检查目标IAM角色的信任策略

找到报错中<cluster role arn>对应的IAM角色,进入AWS控制台的IAM角色详情页,查看信任关系配置,确保当前用户的ARN(<user arn>)被允许扮演该角色:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": "<user arn>"
      },
      "Action": "sts:AssumeRole"
    }
  ]
}

如果没有这条规则,添加后保存。

2. 检查当前用户的IAM权限

确保当前用户的IAM策略中包含允许sts:AssumeRole操作的权限,目标资源为上述集群角色ARN:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "sts:AssumeRole",
      "Resource": "<cluster role arn>"
    }
  ]
}

如果用户没有相关权限,需要由管理员添加该策略。

3. 验证kubeconfig配置正确性

检查本地~/.kube/config文件中的用户配置片段,确认exec命令参数正确,特别是--role-arn字段是否指向正确的集群角色ARN:

users:
- name: eks-cluster-user
  user:
    exec:
      apiVersion: client.authentication.k8s.io/v1beta1
      command: aws
      args:
      - eks
      - get-token
      - --cluster-name
      - your-eks-cluster-name
      - --role-arn
      - <cluster role arn>

如果配置有误,修正后保存。

4. 手动测试角色切换

直接执行AWS CLI命令验证是否能成功获取临时凭证:

aws sts assume-role --role-arn <cluster role arn> --role-session-name test-kubectl-session
  • 如果该命令报错,说明IAM权限问题未解决,回到步骤1和2排查;
  • 如果命令成功返回临时凭证,再重新执行kubectl命令测试。

5. 验证EKS RBAC权限(角色切换成功后仍有问题)

如果成功获取凭证但kubectl操作仍失败,需要确认扮演的IAM角色对应的K8s RBAC权限是否足够:

  • 确保该IAM角色已通过ClusterRoleBinding或RoleBinding绑定到具有对应操作权限的K8s角色(比如cluster-admin或自定义角色)。

内容的提问来源于stack exchange,提问作者Srikar Marupaka

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 09:48:19